How does policy controls on fine-tuning data satisfy CPNI requirements?

Kastra enforces policy controls on fine-tuning data at the moment of execution and writes a signed evidence record for every training record. Auditors get a complete, append-only trail of who attempted what, what policy fired, why the decision was made, and what data was touched. This evidence maps directly to CPNI, GDPR, SOC 2 control families.